Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Harald — An in-memory minimal CPU for agnostic on-the-fly protocols creation | Kitploit
Tools/GitHubGitHub/gmh5225/harald
ExploitationIDS/IPS EvasionScripting & AutomationNetwork SecurityPenetration TestingCommand and ControlUtilities & FrameworksRed TeamingPayload Development
GitHubgmh5225/harald

Harald

An in-memory minimal CPU for agnostic on-the-fly protocols creation

161 year agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Harald CPU

Harald is an in-memory tiny high-level CPU, able to process a set of instructions to generate application-layer protocols to be used over a given network protocol (TCP/UDP).

Harald will consume a stream of OPCODES and apply different transformations to the payload for it to be suitable for the defined application-layer protocol.

[!TIP] Why Harald? You may know Harald Gormsson, king of Denmark, for his nickname: Blátǫnn, or how we pronounce it nowadays, Bluetooth. The technology was named after Harald's nickname as he connected the Danish and Viking kingdoms back then. So I'm naming this after his firstname.

Diagram

Harald behaves as a CPU. It follows a set of OPCODES that define actions. A PROTOCOL. Harald will process the required operations to create the required protocol on the fly.

Once the PROTOCOL is provided, Harald will iterate over the PAYLOAD to be sent by traversing the entire PROTOCOL once for every fragment. I.e.: If the payload had to be split in multiple fragments, Harald will use the same protocol for every fragment, executing every action defined in the protocol against the current payload fragment.

Harald holds a number of registries to be used by the protocol to store values. These registries can be used to perform multiple operations, such as addition, substraction, encoding and decoding... etc.

Harald dynamically allocates an array of results where the protocol can store the responses to each request performed upon sending a payload fragment.

Harald high-level diagram

Opcodes

Harald supports a variety of Opcodes to be provided as a protocol. Harald will perform a set of high-level operations upon receiving a given Opcode. Each Opcode expects a predefined set of arguments with a predefined length.

OPCODE::NºDescriptionARGS::Size
H_F_APPEND::0x01Appends the following N Bytes to the end payloadSize::4, NBytes::N
H_F_PREPEND::0x02Prepends the following N Bytes to the end payloadSize::4, NBytes::N
H_F_SPLIT::0x03Splits the Payload in fragments of the given sizeSize::4
H_F_PAYLOAD_INJECT::0x04Injects the Payload fragment into the End Payload-
H_F_SOCK_INIT::0x05Initializes the socket connectionIsIPAddress:1, SSL_Enabled::1, TCP/UDP::1, [(HostLen::4,HostName:N)/IPAddress::4], Port::2
H_F_SEND::0x06Sends the constructed End Payload-
H_F_RECV::0x07Receives up to N BytesSize::4
H_F_CLOSE::0x08Closes the socket and cleans-
H_F_INJECT::0x09Injects the requested registry into the End PayloadReg::1
H_F_ENCODE_STR::0x0AEncodes a Payload field to its string representationIsReg::1, [(Payload::1, Field::1)/Reg::1], Format::1
H_F_DECODE_STR::0xA0Decodes the contents of a registry to its numeric representationReg::1
H_F_ENCODE_STRB64::0x0BEncodes a Payload field to its B64string representationPayload::1, Field::1
H_F_COMPUTE_FRAG_LENGTH::0x0DCalculates the next fragment to be sent length-
H_F_SEARCH::0x0ESearches for a given byte pattern of a given N size in a given registryReg::1, Size::4, NBytes::N
H_F_SEEK::0x0FMoves the cursor in a given payload by a given number of bytesPayload::1, Offset::4
H_F_PUSH::0x10Pushes a number of bytes or the contents of a registry into another registryIsReg::1, [Size::4, NBytes::N]/SrcReg::1, DstReg::2
H_F_ADD::0x12Adds two registries or a number to a registryIsReg::1, [Size::4, NBytes::N]/SrcReg::1, DstReg::2
H_F_SUBSTRACT::0x13Substracts two registries or a number to a registryIsReg::1, [Size::4, NBytes::N]/SrcReg::1, DstReg::2
H_F_READ::0x14Reads from a given registry up to the length stored in another registryFromReg::1, SizeReg::1
H_F_STORE::0x15Stores a registry value into Harald's StorageReg::1

HTTP Example

The following Opcode stream will generate the required data to be sent for a communication be understood as HTTP. It will initiate, modify the payload to look like HTTP traffic, send it over an SSL/TLS connection, and close the connection at the end.

H_F_SPLIT, 0x00, 0x00, 0x00, 0xFF,                         // Splits the Payload
H_F_APPEND, 0x00, 0x00, 0x00, 0x46,                           // Appends...
  'P', 'O', 'S', 'T', ' ', '/', ' ',                              // POST / 
  'H', 'T', 'T', 'P', '/', '1', '.', '1', '\r', '\n',             // HTTP/1.1
  'H', 'o', 's', 't', ':', ' ',                                   // Host: 
    'd', 'o', 'm', 'a', 'i', 'n', '.', 'c', 'o', 'm', '\r', '\n', // domain.com
  'C', 'o', 'n', 'n', 'e', 'c', 't', 'i', 'o', 'n', ':', ' ',     // Connection: 
    'c', 'l', 'o', 's', 'e', '\r', '\n',                          // close
  'C', 'o', 'n', 't', 'e', 'n', 't', '-',                         // Content-
    'L', 'e', 'n', 'g', 't', 'h', ':', ' ',                       // Length: 
H_F_COMPUTE_FRAG_LENGTH,                                 // Next Fragment's size
H_F_ENCODE_STR, H_PAY_END_PAYLOAD, H_PAY_FRAGMENT_SIZE, 'u',  // FragSize encode
H_F_INJECT, H_REG_RET,                   // Inject the Fragment Size encoded str
H_F_APPEND, 0x00, 0x00, 0x00, 0x04, '\r', '\n', '\r', '\n', // Append Body begin
H_F_PAYLOAD_INJECT,                                        // Inject the Payload
H_F_SOCK_INIT, 0x01, 0x01, 0x7F, 0x00, 0x00, 0x01, 0x04, 0xD2,    // Init Socket
H_F_SEND,                                    // Send the Payload over the socket
H_F_CLOSE                                        // Close the socket and cleanup 
Download Tool